Gravwell On-the-fly packet capture ingester
752
Refer to Gravwell's Docker guide for information on how to deploy ingester containers.
The Packet Fleet Ingester provides a mechanism to query Google Stenographer instances and have results ingested per-packet into Gravwell. Full documentation is available.
The packetfleet optionally takes several environment variables as configuration overrides (defaults shown):
LISTEN_ADDR=":443" # Host:Port to listen on
TLS=true # Use TLS (default is true, set to false to disable TLS)
URL="https://127.0.0.1:1234" # URL to Stenographer
INTERFACE=eth0 # interface stenographer should listen on
STENO_HOST=127.0.0.1 # stenographer host to bind to
STENO_PORT=1234 # stenographer port to bind to
STENO_SYSLOG=true # enable/disable syslog output for stenographer (default is false)
DISABLE_PACKET_FLEET=FALSE # set to true to disable the packet fleet service and only run stenographer
DISABLE_STENOGRAPHER=FALSE # set to true to disable stenographer and only run packet fleet
Each Stenographer ingester listens on a given port (Listen-Address) and accepts Stenographer queries as an HTTP POST. On receiving a query, the ingester returns an integer job ID, and asynchronously queries the Stenographer instance and begins to ingest the returned PCAP. Multiple in-flight queries can be ran concurrently. Job status can be viewed by issuing an HTTP GET on "/status", which returns a JSON-encoded array of in-flight job IDs.
A simple web interface to submit and view job status is also available by browsing to the specified ingester port.
You can optionally disable either Packet Fleet or Stenographer within the container, in order to simplify deployment considerations without having to create new container images.
See https://docs.gravwell.io for more information on configuring the Packet Fleet ingester.
An example docker invocation:
docker run --name packetfleet -d --cap-add IPC_LOCK --cap-add NET_ADMIN \
-e GRAVWELL_CLEARTEXT_TARGETS="192.168.1.1,192.168.1.2" \
-e GRAVWELL_INGEST_SECRET="IngestSecrets" \
-e LISTEN_ADDR=":443" \
-e INTERFACE="eth1" \
-e STENO_SYSLOG=true \
-v /dev/log:/dev/log \
--network=host gravwell/packetfleet:latest
See https://github.com/gravwell/gravwell/tree/master/ingesters/PacketFleet for source.
Note: The Packet Fleet ingester requires a Linux host.
Content type
Image
Digest
Size
119.6 MB
Last updated
over 5 years ago
docker pull gravwell/packetfleet